i use mcp for security. you can have an airgapped agent that can still call online tools. for example, web search.

however it can't get infected because there is no internet access.

the worst you can do is put your secrets in the web search box

You can have that with CLI.

MCP is just a wrapper on top, there are no inherent differences other than complexity on top.

How do you think MCP work under the hood?